SECURITY·중요도 9·2026. 09. 02.·The Hacker News

Attackers Exploit Critical Switchvox Flaw to Deploy Reverse Shells Without Credentials

── KO ──────────────────

Switchvox의 심각한 취약점을 통해 공격자들이 인증 없이 원격 코드 실행을 수행하고 있습니다.

Sangoma Switchvox의 심각한 보안 취약점인 CVE-2026-9586이 발견되어 공격자들이 인증 없이 원격 코드 실행을 할 수 있게 되었습니다. 이 취약점은 Switchvox SMB Edition 8.3에서 SQL 인젝션을 통해 발생하며, CVSS 점수는 9.3으로 매우 높습니다. 공격자들은 이를 악용하여 루트쉘을 배포할 수 있는 능력을 가지게 됩니다.


── EN ──────────────────

Attackers can exploit a critical vulnerability in Switchvox to execute remote code without authentication.

A severe security vulnerability has been discovered in Sangoma Switchvox, identified as CVE-2026-9586, which allows unauthenticated remote code execution. This critical SQL injection vulnerability affects Switchvox SMB Edition 8.3 and has a high CVSS score of 9.3. Threat actors can exploit this flaw to deploy reverse shells without needing credentials.

원문 보기 →목록으로